Files
homelab/docs/03-networking.md

503 lines
6.5 KiB
Markdown

# Chapter 3 - Networking
> Understanding how traffic flows through the cyber range is one of the most important skills for penetration testing. Before attacking systems, you should understand exactly how hosts communicate, how routers forward packets, and how segmentation affects an attack.
---
# Objectives
After completing this chapter you should understand:
* IPv4 addressing
* Subnets
* Default gateways
* DNS
* Routing
* NAT
* Virtual bridges
* Firewall segmentation
* Dual-homed systems
* Attack paths within the lab
---
# Enterprise Network Overview
Our lab is designed to simulate a small business.
```text
Internet
|
Home Router
|
192.168.1.0/24
|
Proxmox Host
|
vmbr0
|
pfSense
+------------------+------------------+
| | |
vmbr1 vmbr2 vmbr3
Attack LAN Corporate LAN DMZ
10.10.10.0/24 10.10.20.0/24 10.10.30.0/24
```
Only **pfSense** connects these networks together.
No VM can communicate between networks unless pfSense routes the traffic.
---
# IP Addressing Plan
## Home Network
Purpose
Management only.
Subnet
```text
192.168.1.0/24
```
Example
```text
Router 192.168.1.1
Proxmox 192.168.1.100
pfSense WAN 192.168.1.150
```
---
## Attack Network
Subnet
```text
10.10.10.0/24
```
Gateway
```text
10.10.10.1
```
Hosts
```text
Kali
Pivot Host
```
---
## Corporate Network
Subnet
```text
10.10.20.0/24
```
Gateway
```text
10.10.20.1
```
Hosts
```text
DC01
WIN10-01
WIN10-02
FILE01
SQL01
LINUX01
BOF-WIN7
```
---
## DMZ
Subnet
```text
10.10.30.0/24
```
Gateway
```text
10.10.30.1
```
Hosts
```text
WEB01
```
---
# Static Addressing
Infrastructure should always use static IP addresses.
Example:
| Machine | Address |
| ------- | ----------- |
| pfSense | 10.10.10.1 |
| Kali | 10.10.10.10 |
| DC01 | 10.10.20.10 |
| FILE01 | 10.10.20.70 |
| SQL01 | 10.10.20.80 |
| WEB01 | 10.10.30.10 |
This prevents services from changing addresses unexpectedly.
---
# Default Gateway
A default gateway is where traffic is sent when the destination is outside the local subnet.
Example:
Kali
```text
IP Address : 10.10.10.10
Mask : 255.255.255.0
Gateway : 10.10.10.1
```
Suppose Kali connects to:
```text
10.10.20.10
```
Since that address is outside the local subnet, Kali forwards the packet to **10.10.10.1 (pfSense)**.
pfSense then forwards the traffic to the Corporate LAN.
---
# Packet Flow
Example:
Kali scans the Domain Controller.
```text
Kali
10.10.10.10
|
|
V
pfSense
10.10.10.1
10.10.20.1
|
|
V
DC01
10.10.20.10
```
Understanding this flow is critical when troubleshooting firewall rules or pivoting.
---
# DNS
Initially:
Clients use pfSense.
Later:
Corporate machines should use the Domain Controller as their DNS server.
```text
10.10.20.10
```
This enables:
* Active Directory
* Kerberos
* LDAP
* Group Policy
* Service discovery
---
# Linux Bridges
A Linux bridge acts like a virtual Ethernet switch.
```text
vmbr2
+--------+--------+
| | |
WIN10 FILE01 SQL01
```
No routing occurs inside a bridge.
Routing only occurs through pfSense.
---
# Why We Don't Need More Physical NICs
Many beginners think each network requires another Ethernet port.
Not in virtualization.
Each Linux bridge is an isolated virtual switch.
Because every VM exists on the same Proxmox host:
* vmbr1
* vmbr2
* vmbr3
are completely independent even though only vmbr0 uses a physical cable.
This is one of the biggest advantages of virtualization.
---
# Dual-Homed Hosts
A dual-homed host has two network interfaces.
Example:
```text
NIC 1
10.10.10.20
NIC 2
10.10.20.50
```
This machine exists on two networks simultaneously.
It becomes useful for learning:
* Ligolo-ng
* Chisel
* SSH tunneling
* SOCKS proxies
* Meterpreter routing
---
# Network Segmentation
Our lab intentionally separates systems.
Attack Network
* Kali
Corporate
* Users
* Servers
* Active Directory
DMZ
* Public web server
This mirrors a real enterprise where servers and user devices are not placed on the same network.
---
# Example Attack Path
A typical penetration test might follow this route:
```text
Internet
|
V
WEB01
|
Privilege Escalation
|
Credentials
|
Pivot Host
|
Corporate LAN
|
Windows Workstation
|
Domain Controller
|
Domain Admin
```
This sequence demonstrates how attackers rarely compromise a domain controller directly.
---
# Common Networking Commands
Linux
Show interfaces
```bash
ip addr
```
Show routes
```bash
ip route
```
Ping
```bash
ping 10.10.20.10
```
DNS lookup
```bash
nslookup lab.local
```
Traceroute
```bash
traceroute 10.10.20.10
```
---
Windows
Display configuration
```powershell
ipconfig /all
```
Show routing table
```powershell
route print
```
Test connectivity
```powershell
ping 10.10.20.10
```
DNS
```powershell
nslookup dc01.lab.local
```
---
# Troubleshooting
### Cannot Reach Another Network
Check:
* Correct IP address
* Correct subnet mask
* Correct gateway
* Firewall rules
* Bridge assignment
---
### Internet Doesn't Work
Verify:
* WAN IP
* Gateway
* NAT
* DNS
---
### Hosts Cannot Resolve Names
Verify:
* DNS server
* Active Directory DNS
* pfSense DNS Resolver
---
### VM Cannot Communicate
Check:
* Proxmox bridge
* NIC status
* IP address
* Gateway
* pfSense rules
---
# Validation Checklist
Before moving to the next chapter:
* [ ] Understand the purpose of each subnet
* [ ] Verify every VM has the correct gateway
* [ ] Confirm Internet access from Kali
* [ ] Confirm Kali can reach the Corporate LAN
* [ ] Confirm Kali can reach the DMZ
* [ ] Verify DNS resolution
* [ ] Understand packet flow through pfSense
* [ ] Understand why Linux bridges replace physical switches in this lab
---
# Next Chapter
The next chapter covers the deployment of **Active Directory**.
You'll build a realistic Windows domain including:
* Domain Controller
* DNS
* Organizational Units (OUs)
* Users
* Groups
* Group Policy
* Domain-joined workstations
* Service accounts
* Common enterprise misconfigurations for security testing
By the end of the next chapter, you'll have the foundation of a Windows enterprise ready for enumeration, Kerberos attacks, SMB testing, privilege escalation, and lateral movement.